5
CVSSv2

CVE-2013-1214

Published: 24/04/2013 Updated: 30/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The scripts editor in Cisco Unified Contact Center Express (aka Unified CCX) does not properly manage privileges for anonymous logins, which allows remote malicious users to read arbitrary scripts by visiting the scripts repository directory, aka Bug ID CSCuf77546.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified_contact_center_express_editor_software -

Vendor Advisories

A vulnerability in the scripts editor software of the Cisco Unified Contact Center Express (Cisco Unified CCX) could allow an unauthenticated, remote attacker to have read access to scripts that are stored in the Cisco Unified CCX scripts repository The vulnerability is due to improper privilege assignment when a user logs in to the Cisco Unified ...